top of page

Privacy Policy

​

Technology Solutions and Security Consulting LLC.; hereafter referred as “TSSConsult”, registered in Meydan Free Zone, Meydan Dubai, UAE
Email: info@tssconsult.com
Website: www.tssconsult.com

Last Updated: 6 March 2026 Version: 1.1


 
1. Introduction
TSSConsult (“we”, “our”, “us”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website at www.tssconsult.com (“the Website”), use our services, or interact with us. We process personal data in accordance with applicable data protection and privacy laws, including but not limited to the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), the UK GDPR, and other applicable national or regional privacy laws depending on your location. Please read this policy carefully. By using our Website, you acknowledge you have read and understood its contents.

 
2. Who We Are (Data Controller)
The data controller responsible for your personal data is:

TSSConsult - Meydan Free Zone, Meydan Dubai, UAE

Email: info@tssconsult.com

If you have any questions or concerns about how we handle your data, please contact us at the address above.

 
3. What Personal Data We Collect
We may collect and process the following categories of personal data:

3.1 Data You Provide Directly

​Contact form submissions: First name, last name, email address, phone number, company name, address, and any information you include in your message.

​Member registration: Username, email address, password (stored in encrypted form), and profile information.
File Share interactions: Any data submitted through the File Share portal.
Shop/purchases: Name, billing address, email, and payment details (processed securely via third-party payment providers; we do not store card data).

Email communications: Any personal data contained in emails you send to us.
3.2 Data Collected Automatically

​Usage data: Pages visited, time spent on pages, referring URLs, browser type, device type, and operating system.
IP address: Collected for security monitoring and analytics purposes.
Cookie data: As described in our Cookie Policy.

3.3 Data We Do Not Collect
We do not intentionally collect special categories of sensitive personal data (e.g., health, racial or ethnic origin, religious beliefs, political opinions, biometric data) through our Website. Please do not submit such data through our contact forms or communications.

 
4. How and Why We Use Your Data (Legal Basis)
We only process your personal data where we have a valid legal basis. The table below summarises our processing activities:

 

​

​

​

​

​

​

​

​

​

 

 

 

 

 

​
 

 

 

 

 

 

 

 

 

 

 

 

 

Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms. Where we rely on consent, you have the right to withdraw it at any time (see Section 9).

 
5. Marketing Communications
We may send you marketing emails about our services, events, and resources if you have explicitly consented to receive them. You may withdraw your consent at any time by: Clicking the “Unsubscribe” link in any marketing email, or Emailing us at info@tssconsult.com. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

 
6. How We Share Your Data
We do not sell, rent, or trade your personal data. We may share your data with the following categories of third parties only where necessary:

Service Providers (Data Processors):

Wix.com Ltd – Website hosting, CMS, and member management platform. Wix acts as a data processor on our behalf. See Wix’s privacy policy at wix.com/about/privacy.

​Google LLC – Website analytics (Google Analytics). Data may be transferred to and processed in the United States under appropriate safeguards.

​Payment processors – For shop transactions (subject to their own data protection obligations).

​Email service providers – For sending transactional and marketing communications.
Legal Requirements: We may disclose personal data to competent authorities, regulators, or law enforcement agencies where we are legally required to do so.

Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to a successor entity, subject to the same privacy protections.

All third-party processors are contractually required to process your data only on our instructions and in accordance with applicable data protection law.

 
7. International Data Transfers
TSSConsult is based in the UAE. When we transfer personal data across borders, we take appropriate steps to ensure that your data receives an adequate level of protection in accordance with applicable privacy laws. These steps may include: Standard Contractual Clauses (SCCs) or equivalent data transfer mechanisms, Transfers to countries or organisations recognised as providing adequate protection, and/or Other legally recognised safeguards as required by your jurisdiction. If you would like more information about the safeguards applicable to a specific transfer, please contact us at info@tssconsult.com.

 
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:

 

 

 

 

 

 

 

 

 

 

 


 

 

 

 

 

 

 

 

 

 

 

 

 

 

9. Your Privacy Rights
Regardless of where you are located, we are committed to respecting your privacy rights. Depending on your jurisdiction, you may have some or all of the following rights:

Right of access: Request a copy of the personal data we hold about you.
Right to rectification: Request correction of inaccurate or incomplete data.

Right to erasure: Request deletion of your data, subject to legal exceptions.

Right to restriction of processing: Request that we limit how we use your data in certain circumstances.
​Right to data portability: Receive your data in a structured, machine-readable format (where applicable).

​Right to object: Object to processing based on legitimate interests or for direct marketing purposes.

​Right to withdraw consent: Withdraw consent at any time where processing is consent-based, without affecting prior processing.

Right not to be subject to automated decision-making: Request human review of any automated decisions that significantly affect you.

​Right to lodge a complaint: File a complaint with the relevant data protection or privacy authority in your country or region.
To exercise any of these rights, please contact us at: info@tssconsult.com. We will respond to all verified requests within 30 days. In complex cases, we may extend this by a further 60 days and will notify you accordingly. We will not discriminate against you for exercising any of your privacy rights.

 
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include encrypted transmission (HTTPS/TLS), access controls, and periodic security reviews — consistent with our role as a cybersecurity firm. However, no method of data transmission over the internet is completely secure. We cannot guarantee absolute security of data transmitted to our Website. In the event of a data breach that is likely to result in a risk to your rights, we will notify you and the relevant authorities as required by applicable law.

 
11. Children’s Data
Our Website and services are not directed at individuals under the age of 18 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, please contact us immediately at info@tssconsult.com and we will delete it promptly.

 
12. Third-Party Links
Our Website may contain links to third-party websites (e.g., partner pages for Scrut Automation, Seagate, and social media platforms). We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies before providing any personal data.

 
13. Jurisdiction-Specific Disclosures
Privacy laws vary by country and region. Where required by applicable law, we provide the following additional disclosures:

European Economic Area (EEA) and UK residents: Your rights under GDPR and UK GDPR are as described in Section 9. You may lodge a complaint with your national Data Protection Authority (DPA) or, in the UK, the Information Commissioner’s Office (ICO) at ico.org.uk.

UAE residents: Your rights under the UAE PDPL are as described in Section 9. You may contact the UAE Data Office for guidance or to raise a complaint.

California residents (CCPA/CPRA): You have the right to know what personal information we collect, disclose, and sell (we do not sell personal data); the right to delete; the right to opt out of sale; and the right to non-discrimination. To submit a verifiable consumer request, contact us at info@tssconsult.com.

Other jurisdictions: We respect the privacy rights afforded to you under the laws of your country. If you have specific questions about rights applicable to your location, please contact us.

 
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The “Last Updated” date at the top of this document will be revised accordingly. Where changes are material, we will take reasonable steps to notify you (e.g., via a notice on the Website or by email). Continued use of the Website after changes are posted constitutes acceptance of the revised policy.

 
15. Contact Us
For any questions, concerns, or to exercise your data subject rights, please contact:

TSSConsult – Data Privacy Email: info@tssconsult.com Address: Meydan Free Zone, Meydan Dubai, UAE

We aim to resolve all privacy-related queries promptly and transparently.

Data Used
Purpose
Legal Basis
Name, email, phone, message content
Responding to enquiries and contact form submissions
Legitimate interests / Precontractual steps
Contact and engagement data
Providing cybersecurity consulting and related services
Performance of a contract
Account credentials, usage data
Managing member accounts and File Share access
Performance of a contract
Order and billing data
Processing shop transactions
Performance of a contract
Email address, name
Sending marketing communications (newsletters, updates)
Consent
Usage data, cookies
Improving our Website through analytics
Consent
IP address, usage logs
Security monitoring and fraud prevention
Legitimate interests
As required
Compliance with legal obligations
Legal obligation
Data Type
Retention Period
Contact form enquiries
5 years from last contact
Client/service data
Duration of contract + 5 years
Member account data
Duration of account + 1 year after closure
Marketing consent records
Until consent is withdrawn + 1 year
Analytics data
26 months (Google Analytics default)
Financial/transaction records
7 years (legal/tax obligation)
Security logs (IP, access logs)
12 months
bottom of page